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IN THE CLAIMS: 

1 . (Cuirewtly Amended) A method in a data processing system for authenticating a 
request, the method comprising: 

receivin g- bv a first security server, a request jfrom a client; 

performing authentication of the reques t bv the first gecuritv server ; 

addin g, bv the first security server, information to the request to form a modified 
request, wherein the information indicates that the request is from a trusted source; 
[[and]] 

sendin g, bv the first securitv server, the modified request to a web application 

server; 

presenting tlie modified request to each of a pluralitv of components of the web 
a pplication server, wherein each of the plurality of comnonents correspond with a 
respecti ve one of a plurality of securitv servers: and 

validating, bv a one of the nlurality of components that corresponds with the first 
securitv server, tlie modified request. 

2. (Original) The method of claim 1, wherein the request is a request to access data. 

3. (Cuixently Amended) The method of claim. I, wherein the [[data processing 
system]] first securitv server i s a reverse proxy server. 

4. (Original) The method of claim 1, wherein the information includes a user 
identification. 

5. (Currently Amended) The method of claim 1, wherein the information includes an 
identification of the [[data processing systemlj first security server . 

6-9. (Cancelled) 
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10. (Currently Amended) The method of claim [[6]]4, wherein the [[information]] 
user identification is a user name and password. 

1 1 . (Cunently Amended) The method of claim [[6]]L wherein the [[selected]] step of 
validating further comprises deterniining that a value of the informatiou is [[a presence of 
a]] an expected value located in a data structur&rrw ithin a preselected location in the 
request]]. 

1 2. (Currently Amended) The method of claim [[6]]i, wherein each of t he plurality of 
components is impleinented as a restJectivc interceptorrF determining step is executed 
using a set of interceptors]], 

13-17. (Cancelled) 

1 8. (Currently Amended) A data processing system comprising: 
a bus system; 

a communications anit connected to the bus system; 

a memory connected to the bus system, wherein the memory includes a plurality 
of coniponents as a.set of instructions; and 

a processing unit connected to the bus system, wherein the processing unit^ 
responsive to receiving a modified request from a first_security_server of a plurality of 
security servers, executes the set of instructions [[to receive a request from a server, 
wherein the request is originated by a client;]] and presents the request to each of a 
plurality of components of the data processing system, wherein each of the plurahty of 
components corresponds witli a respective one of the plurality of security servers, and 
wh erein the processing unit, responsive to execution of a one of the plurality of 
components that corresponds with the first security server, determines rf detennine]] 
whethe r an expected value of [[selected]] informatio n added to tlie modified request bv 
the first security server is f Frenrescntl l uresent in the request[[;]] and [[process]]processes 
the request[[,]] io response to tlie [[selected infonnationll expected value being present in 
the request. 
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1 9. (Currently Am ended) A network data processmg system comprising: 
a network; 

a plurality of clients connected to the network; 

a first security s erver connected to the network, wherein the first security server 
receives a request from a client to access a resource, perfoTms an authentication process 
with the chent, [[add]]adds information to the request in which the information mdicates 
that the request is from a trusted source to form a modified request, and sends the 
modified request for processing; and 

a second server connected to the network, wherein the second server receives the 
modified request from [[a]]ths firs t security server, presents the modified request to a 
plurality of compopents each respectively corresponding to a one of a plurality of 
security servers, determines whether tlie first server is a trusted server ba^ed on [[the 
information]] a determination made bv a first component of the plurality of components 
that corresponds with the first security server , and provides access to the resource in 
response to a determination that the first server is a trusted server. 

20. (Currently Amended) The network data processing system of claim 19 further 
comprising a Ffthirdll second security server connected to the network, wherein the 
[[third]] second security server receives requests from clients to access [[a]]die resource, 
performs an authentication process with the cbentSj [ [add]] adds information to the 
requests in which the information indicates that the requests are from, a trusted source to 
foim modified requests, and sends the modified requests to the second server for 
processings^ whereiri the second server presents the modified requests of the rrthirdll 
second security server to each of the plurality of components and determines whether the 
second security sever is ajrusted server ba$ed on a determination made bv a second 
componept that corresponds with the second security server, wherein the first component 
and tlie second component provide different security restrictions . 

21. (Original) The network data processing system, of claim 19, wherein the network 
is at least one of a local area network, an intranet, an extranet and an Intemet. 
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22. (Cuirently Amended) The network data processing system of claim 19, wherein 
the [[second server includes]] plurality of comi?onents comprise a set of interceptors in 
which the set of interceptors arc used to determine whether the first security server is a 
trusted server, wherein the request is sent to each of the set of interceptors to determine 
whether the interceptors can handle the request. 

23. (Ori ginal) The network data processing system of claim 19, wherein the second 
server receives the request directly from the client. 

24^28. (Cancelled) 

29. (Cun^ently Amended) A data processing system for processing a request, the data 
processing system comprising: 

receiving means for receiving a modified r equest fi^m a first security serve r of a 
plurality of security servers, wherein the mo_dified r equest is generated from a request 
originated by a client and the modified request includes information.added by the first 
security server : 

a plurality of determining means each for determining whether ttiel[sclcctcd]] 
information [[is represent] ]pre$ent in the reques t has an expected value, wherein each of 
the pluralilA^ of determining means corresponds to one of the plurahty of security servers : 
and 

processing means for processing the request in response to a one of the plurality 
of determining means determioing t he [[selected]] information has die expected 
vdue[[being present in the request]]. 

30. (Currently Amended) The data processing system of claim 29, [[wherein the 
determining means is a first determining means and wherein the request is originated by a 
user at the client and]] wherein the modified request requests access to a resourc e, tile 
data processing system [[and wherein the processing step comprisesll fimher comprising : 
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second deteraiining means for determiTiing whether [[tlie]]a.user of the client is 
authorized to access [[to]] the resource; and 

accessing means for accessing the resource using the modified r equcst in response 
to a determination that the user is authorised. 

3 1 . (Currentl y Amended) The data processing system of claim 29, wherein tlie first 
security server is a reverse proxy server, 

32. (Currently Amended) The data processing system of claim 29, wherein the 
information is an identification of the first security server. 

33. (Currently Amended) The data processing system of claim 29, wherein the 
information is a user name and passwor d of a user of the client , 

34. (Cancelled) 

35. (Currently Amended) The data processing system of claim 29, wherein the 
plurality of detentiining means includes a set of interceptors that can provide different 
security restrictions to a resource . 

36. (Cancelled) 

37. (Currently Amended) A computer program product in a computer readable 
medium for processing a request, the computer program product comprising: 

first instructions for receiving a modified r equest from a first security server, 
wherein the modified r equest is generated by the first security server by modifying 
information in a request originated by a client; 

second instructions for detemiining one of a plurality of interceptors that can 
process the request: 

rfsecondll third instructions for determining whether frselectedll a vahie of the 
information [[is represent] J present in the reques t is an expected value : and 
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r[tfaird]] fouTt]i instructions, responsive to the [[selected]] value of the i nformatjou 
being [[present in the request]] the expected value, for processing the request. 
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